Impact
A flaw in the process-pool implementation of AnyIO causes workers to launch child processes with standard error connected to a pipe that the parent never drains, despite documentation stating that all streams are redirected. If a worker writes enough data to sys.stderr—possibly due to malicious or buggy code—the pipe fills, blocking the worker before it can return its normal response. The awaiting coroutine then remains blocked indefinitely, leading to a denial of service. This issue is classified as a resource exhaustion defect (CWE-770) and a race between I/O and process control (CWE-1322).
Affected Systems
All installations of AnyIO prior to version 4.14.2 are susceptible, particularly those that spawn process‑pool workers executing untrusted code. Only the agronholm:anyio product is affected The fix is included in release 4.14.2, so any version older than that must be upgraded.
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate severity. The EPSS score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA KEV, implying no confirmed exploits yet. The attack vector requires a process‑pool worker that writes large amounts of data to its standard error stream – this may naturally arise from untrusted or buggy worker code. If such a scenario occurs, the blocking can persist forever, leading to denial of service. The flaw aligns with CWE-770 and CWE-1322. Prompt upgrade mitigates risk entirely.
OpenCVE Enrichment
Github GHSA